|
221991
|
9.8 |
CRITICAL
Network
|
doordash
|
doordash
|
In the DoorDash application through 11.5.2 for Android, the username and password are stored in the log during authentication, and may be available to attackers via logcat.
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2019-17397
|
2024-11-21 13:32 |
2019-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221992
|
9.8 |
CRITICAL
Network
|
intelbras
|
iwr_1000n_firmware
|
Intelbras IWR 1000N 1.6.4 devices allow disclosure of the administrator login name and password because v1/system/user is mishandled.
|
CWE-352
Origin Validation Error
|
CVE-2019-17600
|
2024-11-21 13:32 |
2019-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221993
|
5.4 |
MEDIUM
Network
|
gnu opensuse
|
ncurses leap
|
There is a heap-based buffer over-read in the fmt_entry function in tinfo/comp_hash.c in the terminfo library in ncurses before 6.1-20191012.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-17595
|
2024-11-21 13:32 |
2019-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221994
|
5.3 |
MEDIUM
Local
|
gnu opensuse
|
ncurses leap
|
There is a heap-based buffer over-read in the _nc_find_entry function in tinfo/comp_hash.c in the terminfo library in ncurses before 6.1-20191012.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-17594
|
2024-11-21 13:32 |
2019-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221995
|
8.8 |
HIGH
Network
|
jizhicms
|
jizhicms
|
JIZHICMS 1.5.1 allows admin.php/Admin/adminadd.html CSRF to add an administrator.
|
CWE-352
Origin Validation Error
|
CVE-2019-17593
|
2024-11-21 13:32 |
2019-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221996
|
7.5 |
HIGH
Network
|
csv-parse_project fedoraproject
|
csv-parse fedora
|
The csv-parse module before 4.4.6 for Node.js is vulnerable to Regular Expression Denial of Service. The __isInt() function contains a malformed regular expression that processes large crafted input …
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2019-17592
|
2024-11-21 13:32 |
2019-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221997
|
7.5 |
HIGH
Network
|
idreamsoft
|
icms
|
idreamsoft iCMS 7.0.15 allows remote attackers to cause a denial of service (resource consumption) via a query for many comments, as demonstrated by the admincp.php?app=comment&perpage= substring fol…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2019-17583
|
2024-11-21 13:32 |
2019-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221998
|
9.8 |
CRITICAL
Network
|
dormsystem_project
|
dormsystem
|
tonyy dormsystem through 1.3 allows SQL Injection in admin.php.
|
CWE-89
SQL Injection
|
CVE-2019-17580
|
2024-11-21 13:32 |
2019-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221999
|
7.5 |
HIGH
Network
|
dlink
|
dir-412_firmware
|
There are some web interfaces without authentication requirements on D-Link DIR-412 A1-1.14WW routers. An attacker can get the router's log file via log_get.php, which could be used to discover the i…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-17511
|
2024-11-21 13:32 |
2019-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222000
|
6.1 |
MEDIUM
Network
|
sonarsource
|
sonarqube
|
SonarSource SonarQube before 7.8 has XSS in project links on account/projects.
|
CWE-79
Cross-site Scripting
|
CVE-2019-17579
|
2024-11-21 13:32 |
2019-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|